Report by Cloud Security Alliance (CSA)
Identity and Access Gaps in the Age of Autonomous AI
Key Findings
57% of organizations report moderate or high confidence in identity scoping for AI agents.
74% of organizations say AI agents often receive more access than necessary.
Responsibility for AI agent identity and access is fragmented: 28% of organizations assign primary ownership to security leads, 21% to development/engineering, 19% to IT, and 9% to IAM teams.
22% of organizations report that access frameworks are applied very consistently to AI agents.
68% of organizations cannot clearly distinguish between human and AI agent activity.
52% of organizations use workload identities for AI agents, 43% rely on shared service accounts, and 31% allow agents to operate under human user identities.
49% of organizations disable identities or revoke tokens as containment actions, 42% terminate the compute environment where an agent runs, and 33% remove or modify access policies in real time.
73% of organizations expect AI agents to become vital within the next year.
AI agents operate across enterprise workflows: 67% are task automation agents, 52% are research agents, 50% are developer-assist agents, and 50% are security or monitoring agents.
85% of organizations use AI agents in production environments.
79% of organizations believe AI agents create new access pathways that are difficult to monitor.
32% of organizations are uncertain how much time is required to implement and maintain authentication or credential handling for a typical AI agent.
52% of organizations say AI agents inherit access originally intended for humans or other systems at least sometimes.
33% of organizations do not know how often AI agent credentials are rotated.